Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3d6926f636f4ae8…

MALICIOUS

PDF

6.3 KB
MD5: cee141304c65a58b5ee123bf17289f99 SHA-1: 6079e19e7505bb10cd81b21d8c584efb733be1ec SHA-256: d3d6926f636f4ae89f57e6cad16b60c742ea596c9b613adbbe413620c82fcb47
66 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript T1204.002 Malicious File

The PDF file was flagged as malicious by an ML classifier with high confidence. It contains embedded JavaScript streams that exhibit obfuscation techniques, including hex escape sequences and long encoded blobs. The primary purpose of the script appears to be downloading and executing a second-stage payload from the embedded URL: http://www2.simplescaners.it.cx/?ele7r=ic%2FSm6%2FY4dKW4c7XoJaklquZ2eDRdKSkmaKmoMisl5Ggi%2Bbmop2YaqqmoaapnpWZz9Srl6aki83HmeSwu8G7ktXcx56hi%2BWX.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www2.simplescaners.it.cx/?ele7r=ic%2FSm6%2FY4dKW4c7XoJaklquZ2eDRdKSkmaKmoMisl5Ggi%2Bbmop2YaqqmoaapnpWZz9Srl6aki83HmeSwu8G7ktXcx56hi%2BWX

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0005_000.js
b0f1aad925f41566b97bf214fb9d50d238d05af7d8cf54e18c6ebef9e78b8d3f
pdf-javascript-stream PDF /JS object 5 at offset 0x1A6 5735 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s). Carved artifact contains 1 long hex-escaped blob(s).
javascript_obj0005_001.js
57731358c58ccd5c7a31f78d6f4b6d0f82bf39ae97a952cfd98fd4cec40fce7d
pdf-javascript-stream PDF /JS object 5 at offset 0x1C9 6018 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s). Carved artifact contains 1 long hex-escaped blob(s).